HIGAET Identity & Access Security
Learn identity-first defense and build MFA rollouts, lifecycle workflows, privileged access reviews, and directory monitoring in practice labs.
Duration
6 weeks · 8-10 hours/week
Level
Intermediate
Delivery
Online
Status
Open for enrollment
Why this technology matters.
Identity and access security is the identity-first approach to defense: making sure the right people and systems can reach the right resources — and nothing else. It matters now because stolen credentials and overbroad access are among the most common paths into an organization. This course teaches the lifecycle habits that keep access correct over time, in practice labs.
You will use these controls in IT and security teams: directory structures with groups and roles, MFA and conditional access policies, and joiner-mover-leaver workflows with approval trails. This solves access sprawl and lingering privileges that accumulate as people change roles. It does not solve everything: MFA does not fix unmanaged devices on its own, reviews do not fix unclear role definitions, and policies do not fix processes nobody follows.
By the end you will be able to build a directory structure with groups, roles, and naming standards, an MFA and conditional access policy set for a lab tenant, and a joiner-mover-leaver workflow with privileged access reviews and just-in-time controls.
Why this course exists
The gap is between creating accounts once and keeping access correct as people join, move, and leave. This course closes it with an arc from structure to policy to lifecycle to review: organize directories and roles, enforce MFA and conditional access, run lifecycle workflows with approvals, then review privileged access on a repeatable cycle.
Know exactly what you're signing up for.
Who is this for
Prerequisites
- No previous identity security experience required
- Basic directory and user account familiarity
- Comfort with admin consoles and policies
Technologies & tools
Skills you'll gain
A 6 weeks arc, module by module.
- Module 01
Module 01 — Foundations: Identity models and access principles
- Module 02
Module 02 — Directories: Users, groups, and role design
- Module 03
Module 03 — Authentication: MFA and conditional access
- Module 04
Module 04 — Core: Lifecycle workflows and approvals
- Module 05
Module 05 — Privilege: Reviews, vaulting, and session controls
- Module 06
Module 06 — Capstone: Identity-hardened lab with review report
Practical Training Flow
Learning → Guided Labs → Independent Practice → Industry Project → Capstone → Portfolio → Career Preparation. Practical hours are tracked alongside instructional hours and surfaced on the certificate.
Delivery as HIGAET Practical Training / Experiential Learning.
What you'll be able to do.
- Build directory structures with groups, roles, and naming standards
- Design MFA and conditional access policies for lab tenants
- Develop joiner-mover-leaver workflows with approval trails
- Deploy privileged access reviews and just-in-time controls
- Integrate single sign-on for sample lab applications
- Evaluate access logs for anomalous sign-in patterns
- Secure service accounts and API credentials defensively
- Automate access review reminders and evidence exports
You will build.
Every project ships as HIGAET Practical Training / Experiential Learning — portfolio-ready work, not exercises.
- Project 01
Directory structure with roles and standards
- Project 02
MFA and conditional access policy set
- Project 03
Joiner-mover-leaver workflow with approvals
- Capstone
Identity-first defense with lifecycle workflows, MFA policies, and privileged access reviews
Speak the language first.
- Directory structure
- Organized groups, roles, and naming standards that make user and system accounts easy to manage.
- Least privilege
- Giving each account only the permissions it needs so a compromised account causes less harm.
- Multi-factor authentication (MFA)
- Requiring two or more proofs of identity, such as a password plus a phone code, at sign-in.
- Conditional access
- Policies that allow or challenge sign-ins based on conditions like device, location, or risk level.
- Joiner-mover-leaver workflow
- Standard steps for creating, updating, and removing access as people join, change roles, or leave.
- Approval trails
- Recorded requests and approvals for access changes that show who authorized what and when.
- Privileged access review
- Periodic checks of high-power accounts to confirm each one is still needed and correctly scoped.
- Just-in-time access
- Granting elevated permissions only for a short approved window instead of permanently.
- Directory monitoring
- Watching sign-in and change logs for unusual identity activity such as mass permission grants.
Fix, check, and go deeper.
Troubleshooting & common mistakes
MFA rollout locks out legitimate lab users
Check enrollment status and fallback methods, confirm time sync on authenticator apps, and provide temporary verified bypass with an expiry.
Conditional access policy blocks an entire lab group
Review policy conditions and assignments in audit logs, narrow the scope to the intended group, and test with a pilot account first.
Leaver accounts retain access after departure
Audit HR or roster feeds against the directory, disable orphaned accounts, and fix the workflow trigger that missed the event.
Privilege review flags too many stale admin accounts
Sort by last use and owner, remove or downgrade confirmed-stale accounts, and set shorter review cycles for remaining privileged roles.
Just-in-time elevation never expires
Inspect the time-bound policy and approval ticket linkage, correct the duration setting, and revoke lingering active elevations.
Before you move on, you should be able to
- Build directory structures with groups, roles, and naming standards
- Design MFA and conditional access policies for lab tenants
- Develop joiner-mover-leaver workflows with approval trails
- Deploy privileged access reviews and just-in-time controls
- Explain how least privilege reduces identity risk
- Evaluate directory monitoring logs for unusual access activity
Start your application.
Share a few details and a HIGAET advisor will reach out within one business day with next steps.
Common questions
Continue in Cybersecurity.
HIGAET Cybersecurity Engineering
Learn defensive security foundations and build hardened lab networks, secure endpoints, and monitoring workflows through guided HIGAET Practical Training / Experiential Learning.
View CourseHIGAET Cloud Security
Learn to secure cloud accounts, storage, and workloads while building identity policies, logging pipelines, and misconfiguration reviews in controlled labs.
View CourseHIGAET Application Security
Learn secure coding, authentication design, and defensive testing while building threat models, code reviews, and pipeline checks for sample applications.
View CourseReady to start HIGAET Identity & Access Security?
A 6 weeks course — Cybersecurity.